HomeAboutServicesCalculatorsContactInsightsInvestor LoginQuick LinksBook Free Consultation

Home / Insights / Insurance

Rytvae Consulting — AMFI Registered Mutual Fund Distributor (ARN-265474), EUIN E091320

Insurance Investor Education Initiative

Cyber and D&O liability: the exposures balance sheets miss

Traditional business insurance is built around physical loss — fire, theft, damage in transit. The two exposures that have grown fastest involve no physical loss whatsoever, and most balance sheets carry them uninsured.

By Srinivas Kambhampati (ARN-265474) Published 4 min read

What cyber insurance actually pays for

It divides into two halves, and the first is the one businesses use most.

First-party costs are what you spend responding to your own incident: forensic investigation to establish what happened, legal advice on notification obligations, notifying affected individuals, credit monitoring where appropriate, public relations, and business interruption while systems are down. In the majority of incidents this is the bulk of the claim.

Third-party liability covers claims brought against you — by customers whose data was exposed, by contractual counterparties, and regulatory proceedings and penalties where these are insurable.

With India's data protection framework placing defined obligations on entities handling personal data, the notification and response costs alone have become material for businesses that hold customer records — which now includes most of them.

Buy the response, not just the limit

The most valuable part of a cyber policy is frequently not the indemnity but the incident response panel: pre-arranged access to forensic specialists, breach counsel and communications support, reachable immediately.

The reason is that cost in a cyber incident is driven by the first forty-eight hours. A business improvising — deciding whether to take systems down, who to call, whether and when to notify — makes expensive mistakes under pressure. One with a number to call and a plan does not.

So when comparing policies, look past the limit. Ask who is on the panel, how quickly they respond, and whether you are required to use them. A smaller limit with a strong response capability is generally worth more than the reverse.

What D&O protects, and who it protects

Directors and officers liability responds to claims alleging a wrongful act by an individual in their capacity as a director or officer — breach of duty, misstatement, regulatory non-compliance, employment practices claims, and actions brought by shareholders, regulators, employees or creditors.

The essential point, and the one most often missed: it protects individuals personally. Directors' liability in these circumstances is not limited by the company's limited liability. Personal assets can be exposed. D&O covers the defence costs and any damages, which is why it matters even where the allegation is ultimately unfounded — defending it is expensive regardless of outcome.

It is not only a listed company product. Private companies, companies with outside investors, and any business with independent directors on the board have a real exposure. Independent directors in particular frequently ask whether cover is in place before accepting an appointment, and are right to.

Claims-made, and why that word matters

Both policies are almost always written on a claims-made basis. Cover responds to claims first made against you during the policy period, not to acts committed during it.

Three consequences follow, and each has caught businesses out.

  • A gap in cover is permanent. Let the policy lapse and a claim arriving later about an earlier act has no cover, even though you were insured when the act occurred.
  • Retroactive date matters. The policy may exclude acts before a stated date. On a first purchase this can leave historic exposure uncovered.
  • Run-off cover is needed on exit. A director resigning, or a company being sold, needs run-off to respond to claims made after the policy ends about acts during their tenure. It is bought at that point, not afterwards.

Where they sit alongside everything else

Neither of these overlaps with the physical covers a business already holds. A fire policy, marine and contractors all risk, and workmen compensation all respond to physical events and statutory liabilities. Cyber and D&O respond to allegations and to incidents with no physical dimension at all.

That is precisely why they get missed in a renewal review that works through the existing schedule. The exposure does not appear anywhere on last year's list. The practical test is simpler than an insurance audit: ask what your business would do on a Monday morning if customer data were exposed, and what a director would do personally if a regulator wrote to them. If neither answer involves an insurer, both exposures sit on the balance sheet.

Frequently asked questions

What does cyber insurance cover?

First-party response costs — forensics, legal advice, notification, credit monitoring, public relations and business interruption — and third-party liability for claims by affected individuals or counterparties, including insurable regulatory proceedings. Response costs are the bulk of most claims.

Is the policy limit the most important thing to compare?

Often not. The incident response panel matters more, because cost is driven by the first forty-eight hours. Pre-arranged access to forensic specialists and breach counsel usually saves more than a larger limit does. Ask who is on the panel and how fast they respond.

Who does D&O insurance protect?

The individual directors and officers personally, including their personal assets. Liability for a wrongful act in that capacity is not limited by the company’s limited liability, and D&O covers defence costs and damages — which matters even when an allegation is ultimately unfounded.

Is D&O only relevant to listed companies?

No. Private companies, businesses with outside investors and any board with independent directors carry a real exposure. Independent directors commonly ask whether cover is in place before accepting an appointment.

What does claims-made mean?

Cover responds to claims first made against you during the policy period, not to acts committed during it. So a lapse in cover is permanent for past acts, the retroactive date limits how far back cover reaches, and run-off cover is needed when a director leaves or a company is sold.

We already have fire and liability cover. Is that enough?

Those respond to physical loss and statutory liabilities. Cyber and D&O respond to incidents and allegations with no physical dimension, which is why they are missed in reviews that work through the existing schedule. Ask what you would do if customer data were exposed, or if a regulator wrote to a director personally.

Rytvae Consulting — AMFI Registered Mutual Fund Distributor (ARN-265474), EUIN E091320. Rytvae Consulting is a distributor of mutual fund and insurance products and is not a SEBI-registered Investment Adviser. Any assistance offered is incidental to distribution.

Insurance is the subject matter of solicitation. Cover, exclusions, waiting periods, sub-limits and conditions differ between insurers and are governed entirely by the policy wording issued to you — read it before you rely on it. This article is general information, not advice on any specific policy, and not tax or legal advice. Taxation depends on your own facts and on law as it stands from time to time; confirm with your chartered accountant. Rytvae Consulting distributes insurance through IRDAI-regulated partners. See our full disclosures and disclaimers.